Privacy policy
Version 1.7 – 26 September 2026
This policy explains which personal data NONI processes, why it is used and which rights you have. NONI is a nutrition diary with optional personalized summaries and AI-assisted guidance. NONI is not a medical device and does not replace medical or nutritional advice.
1. Controller and contact
The controller is Cloud.Seven Digital Solutions GmbH, Mittererstraße 21, 3100 St. Pölten / Unterwagram, Austria, company register number FN 653330f, Regional Court St. Pölten.
You can contact us through the contact form or at office@cloud7.digital.
2. Scope
This policy applies to the native NONI app for iPhone and iPad and to the public NONI.CC product and support website.
3. Data we process
- Account and authentication data: email address, internal user ID, sign-in and confirmation times and session data. Your password is processed through Supabase Auth; NONI does not receive it in plain text.
- Profile and goal data: name, optional phone number and date of birth, age, sex, height, current and target weight, activity level, nutrition goal, calorie, macro and hydration targets, language and unit system.
- Nutrition and body data: meals, foods, nutrition values, amounts, barcodes, drinks, hydration, weight entries, saved entries and calculated daily totals.
- Photos and AI inputs: food, drink, menu or nutrition-label photos you select, and the profile, goal, nutrition, hydration and, where enabled, Apple Health values required for a review you start.
- Technical data: necessary session information, language, random session ID, limited feature events, timestamps, error codes and counters used to prevent abuse. NONI does not use device fingerprinting.
- Consent records: consent type, document version and the time consent was given or withdrawn.
- Apple Health data: only the values you separately allow, together with measurement times, units and technical source information.
- NONI Pro data: product ID, transaction and original transaction IDs, an app account identifier linked to your NONI account, entitlement status, expiry and renewal information. NONI does not receive full card or bank details.
4. Purposes and legal bases
- Account, authentication, synchronization, export, subscription validation and app functions you request are based on Article 6(1)(b) GDPR.
- We process body, nutrition and weight data, and personalized or user-requested AI functions, with your explicit consent under Articles 6(1)(a) and 9(2)(a) GDPR where health data is involved.
- Security, error analysis, abuse prevention and strictly limited internal usage statistics are based on Article 6(1)(f) GDPR. Our legitimate interest is to operate NONI securely, reliably and clearly.
- We process contact requests to respond to your enquiry and, where applicable, to take pre-contractual steps under Article 6(1)(b) GDPR, and for secure and traceable communication under Article 6(1)(f) GDPR.
- Where processing is required to comply with legal obligations, it is based on Article 6(1)(c) GDPR.
Account and profile data is required for a personal NONI account. Health-related information, Apple Health and photos are optional. Without the relevant consent or device permission, the affected personalized functions are unavailable.
5. Photos and NONI AI
A photo is processed only after you select or take it and start analysis. It is sent over an encrypted connection through NONI services to Google Cloud and to Vertex AI for the requested analysis. NONI does not store the photo in its own photo archive. Recognized results that you confirm may be stored as nutrition entries.
When you start a NONI AI review, only the profile, goal, nutrition and hydration values required for that function are processed. The “What could I improve today?” function may additionally use enabled activity, sleep, HRV and resting-heart-rate values, including aggregated 28-day comparisons. Your name, email address and phone number are not included in the model prompt.
Under the Google Cloud terms, Google does not use Vertex AI customer data to train or fine-tune its models without prior permission. Google may temporarily cache inputs and outputs and log prompts for abuse monitoring under its terms. NONI does not use Grounding with Google Search or Google Maps for these functions and does not enable its own logging of complete model requests or responses.
AI outputs are estimates. They are guidance, must be reviewed before saving and are not used for automated decisions producing legal or similarly significant effects.
6. Product, food and recipe data
NONI's own product catalogue, the German nutrient database BLS and imported USDA FoodData Central datasets are searched inside the NONI infrastructure. Normal searches do not transmit user data or search terms to BLS or USDA.
For product and barcode searches, the NONI server may send a barcode or your search term to Open Food Facts. Open Food Facts receives no NONI user ID or email address. Product data you confirm may be added to the shared NONI catalogue without being linked to your account. Personal meals and consumed amounts remain separate.
For recipe suggestions, NONI may send broadly rounded calorie and protein filters and the required language to Spoonacular. Spoonacular receives no NONI user ID, email address, diary content, weight data or photos. Recipe content may be sent to Vertex AI for translation or a Thermomix adaptation you request, without adding account or diary data. Displayed recipe and nutrition data is external information or estimates that you should review.
7. Internal usage analysis
NONI collects limited technical feature events, such as opening the coach, generating, viewing, rating or accepting a recommendation, or adding a food, drink or weight entry. The event type, timestamp, internal user ID, a random session ID and a few strictly limited values such as language, position or error reason are stored.
This does not include meal or food names, specific nutrition or weight values, body measurements, photos, email addresses, phone numbers, free text or location data. NONI does not create advertising profiles or use an external advertising or analytics platform such as Google Analytics or Meta Pixel. Only authorized NONI administrators can access this analysis.
8. Apple Health
Apple Health is optional. You separately decide whether NONI may read steps, active energy, body weight, resting heart rate, sleep and sleep stages, HRV, body fat percentage, lean body mass and waist circumference. After your explicit consent and iOS permission, NONI reads values from the previous 30 days and stores encrypted, account-linked copies through Supabase.
The values are used for your personal activity, recovery, daily and progress views. Enabled activity, sleep, HRV and resting-heart-rate values may be sent to Vertex AI only for an improvement review you start. Your calorie target is not changed without your explicit confirmation. The current version of NONI does not write data to Apple Health.
You can change permissions in iOS at any time. Disconnecting under “More → Apple Health” deletes the imported Apple Health copies from NONI and withdraws consent for future processing. Data in Apple Health remains unaffected.
9. NONI Pro and Apple App Store
Purchases and subscriptions are processed by Apple through the App Store and StoreKit. Apple handles payment. NONI does not receive full credit-card or bank details. To validate and restore NONI Pro, NONI processes signed Apple transaction and server-notification data, product ID, status, expiry, renewal status, trial status and the app account identifier linked to your NONI account.
10. Recipients, service providers and international transfers
- Supabase provides authentication, database and technical platform services.
- Google Cloud provides server, security and AI services.
- Open Food Facts and Spoonacular receive only the limited request data described in section 6.
- Apple processes App Store purchases and subscriptions and sends NONI the signed data required to validate access.
- An email delivery service is used for the contact form; the message is delivered to office@cloud7.digital.
Processing and storage takes place, where configured for the respective service, in data centres in Europe. Service providers may engage subprocessors under their terms. Where data is processed outside the European Economic Area, the applicable safeguards and transfer mechanisms are used.
11. NONI.CC and contact
On the NONI website, technical server and request data such as time, requested path, response status and necessary network and security metadata is generated when a page is opened. The website does not use advertising or third-party analytics and does not use device fingerprinting.
When you submit the contact form, NONI processes your name, email address, subject and message. The data is validated server-side, processed through the Supabase-based contact infrastructure and delivered to office@cloud7.digital by an email delivery service. The content is not stored permanently in the NONI database. Only minimized technical counters are stored briefly to prevent abuse. The form does not subscribe you to newsletters or marketing.
The app stores necessary session and language settings, a random session ID and reminders you create on the device. Reminders are scheduled as local iOS notifications and are not sent as push notifications through a NONI server.
12. Cookies and similar technologies
NONI may use technically necessary cookies or similar technologies on the website to provide essential functions. No non-essential analytics or marketing technologies are currently used.
If additional technologies, such as analytics or marketing technologies, are used in the future, we will provide appropriate information and, where required, obtain your consent beforehand.
13. Retention and deletion
- Account, profile, nutrition, body, consent and account-linked NONI Pro data is generally stored until account deletion.
- Internal usage events are deleted after no more than twelve months.
- Technical request and abuse-prevention counters are deleted after no more than two days.
- Standard logs for NONI services and the website are currently retained for 30 days.
- Data at Vertex AI may be processed or temporarily cached under the conditions described in section 5.
- Contact and support communication is deleted when it is no longer required for its purpose and generally after no more than twelve months. Longer retention occurs only where statutory retention obligations, the establishment, exercise or defence of legal claims, or an unresolved ongoing matter requires it.
- Technical data used to process App Store subscriptions is retained only for as long as necessary for secure processing, generally for no more than seven days.
You can delete your account in the app under “More → Delete account & data”. This deletes the authentication account and app data directly linked to it. Global product catalogue data without an account link remains. Minimized technical processing records may remain temporarily until the end of their short retention period, as may data in necessary provider backups. Instructions are also available under Delete account.
14. Your rights
Subject to the GDPR, you have rights including access, rectification, erasure, restriction, data portability and objection. You may withdraw consent at any time for the future; withdrawal does not affect the lawfulness of earlier processing. For a request or withdrawal, contact office@cloud7.digital. We may request reasonable proof of identity for security.
You may also lodge a complaint with the Austrian Data Protection Authority, Barichgasse 40–42, 1030 Vienna, Austria, email dsb@dsb.gv.at.
15. Changes
We update this policy when functions, recipients or legal bases change. For material changes, we provide information in the app and request renewed confirmation or consent where required.